{"schema_version":1,"title":"Libexpat Project Libexpat vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 29 vulnerabilities in Libexpat Project Libexpat: 0 in the last 7 days and 3 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-76957, was published on 20 August 2026.","url":"https://junglewise.ai/threats/technologies/libexpat","json_url":"https://junglewise.ai/threats/technologies/libexpat.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/libexpat","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":3,"all_time":29,"critical":3,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":3,"last_365_days":25},"latest":[{"cve":"CVE-2026-76957","cvss":4.9,"epss":0.0015,"slug":"cve-2026-76957-libexpat-use-after-free-in-custom-encoding-callbacks","title":"libexpat use-after-free in custom encoding callbacks","severity":"medium","exploited":false,"published_at":"2026-08-20T05:16:29.747+00:00","url":"https://junglewise.ai/threats/cve-2026-76957-libexpat-use-after-free-in-custom-encoding-callbacks"},{"cve":"CVE-2026-76956","cvss":5.9,"epss":0.0045,"slug":"cve-2026-76956-libexpat-hash-flooding-denial-of-service-via-mishandled-entropy","title":"libexpat hash flooding denial of service via mishandled entropy generation","severity":"medium","exploited":false,"published_at":"2026-08-20T05:16:29.61+00:00","url":"https://junglewise.ai/threats/cve-2026-76956-libexpat-hash-flooding-denial-of-service-via-mishandled-entropy"},{"cve":"CVE-2026-66046","cvss":7.5,"epss":0.0075,"slug":"cve-2026-66046-expat-xml-parser-denial-of-service-via-quadratic-complexity","title":"Expat XML parser denial of service via quadratic complexity","severity":"high","exploited":false,"published_at":"2026-08-18T15:16:57+00:00","url":"https://junglewise.ai/threats/cve-2026-66046-expat-xml-parser-denial-of-service-via-quadratic-complexity"},{"cve":"CVE-2026-56412","cvss":4.9,"slug":"cve-2026-56412-libexpat-use-after-free-in-docdatasection","title":"libexpat use-after-free in doCdataSection","severity":"medium","exploited":false,"published_at":"2026-06-21T17:16:44.657+00:00","url":"https://junglewise.ai/threats/cve-2026-56412-libexpat-use-after-free-in-docdatasection"},{"cve":"CVE-2026-56411","cvss":6.9,"slug":"cve-2026-56411-libexpat-integer-overflow-in-xmlwf-enddoctypedecl","title":"libexpat integer overflow in xmlwf endDoctypeDecl","severity":"medium","exploited":false,"published_at":"2026-06-21T17:16:44.523+00:00","url":"https://junglewise.ai/threats/cve-2026-56411-libexpat-integer-overflow-in-xmlwf-enddoctypedecl"},{"cve":"CVE-2026-56410","cvss":6.9,"slug":"cve-2026-56410-libexpat-xmlwf-integer-overflow-in-resolvesystemid","title":"libexpat xmlwf integer overflow in resolveSystemId","severity":"medium","exploited":false,"published_at":"2026-06-21T16:16:28.36+00:00","url":"https://junglewise.ai/threats/cve-2026-56410-libexpat-xmlwf-integer-overflow-in-resolvesystemid"},{"cve":"CVE-2026-56409","cvss":6.5,"slug":"cve-2026-56409-libexpat-xmlwf-integer-overflow-in-output-filename-handling","title":"libexpat xmlwf integer overflow in output filename handling","severity":"medium","exploited":false,"published_at":"2026-06-21T16:16:28.23+00:00","url":"https://junglewise.ai/threats/cve-2026-56409-libexpat-xmlwf-integer-overflow-in-output-filename-handling"},{"cve":"CVE-2026-56408","cvss":6.9,"slug":"cve-2026-56408-libexpat-integer-overflow-in-copystring","title":"libexpat integer overflow in copyString","severity":"medium","exploited":false,"published_at":"2026-06-21T16:16:28.11+00:00","url":"https://junglewise.ai/threats/cve-2026-56408-libexpat-integer-overflow-in-copystring"},{"cve":"CVE-2026-56407","cvss":6.9,"slug":"cve-2026-56407-libexpat-integer-overflow-in-doprolog-entity-handling","title":"libexpat integer overflow in doProlog entity handling","severity":"medium","exploited":false,"published_at":"2026-06-21T16:16:27.987+00:00","url":"https://junglewise.ai/threats/cve-2026-56407-libexpat-integer-overflow-in-doprolog-entity-handling"},{"cve":"CVE-2026-56406","cvss":6.9,"slug":"cve-2026-56406-libexpat-integer-overflow-in-xml-parsebuffer","title":"libexpat integer overflow in XML_ParseBuffer","severity":"medium","exploited":false,"published_at":"2026-06-21T16:16:27.87+00:00","url":"https://junglewise.ai/threats/cve-2026-56406-libexpat-integer-overflow-in-xml-parsebuffer"},{"cve":"CVE-2026-56405","cvss":6.9,"slug":"cve-2026-56405-libexpat-integer-overflow-in-getattributeid","title":"libexpat integer overflow in getAttributeId","severity":"medium","exploited":false,"published_at":"2026-06-21T16:16:27.74+00:00","url":"https://junglewise.ai/threats/cve-2026-56405-libexpat-integer-overflow-in-getattributeid"},{"cve":"CVE-2026-56404","cvss":6.9,"slug":"cve-2026-56404-libexpat-integer-overflow-in-addbinding","title":"libexpat integer overflow in addBinding","severity":"medium","exploited":false,"published_at":"2026-06-21T16:16:27.62+00:00","url":"https://junglewise.ai/threats/cve-2026-56404-libexpat-integer-overflow-in-addbinding"},{"cve":"CVE-2026-56403","cvss":6.9,"slug":"cve-2026-56403-libexpat-integer-overflow-in-storeatts","title":"libexpat integer overflow in storeAtts","severity":"medium","exploited":false,"published_at":"2026-06-21T16:16:26.59+00:00","url":"https://junglewise.ai/threats/cve-2026-56403-libexpat-integer-overflow-in-storeatts"},{"cve":"CVE-2026-56132","cvss":6.9,"slug":"cve-2026-56132-libexpat-heap-buffer-overflow-in-doprolog","title":"libexpat heap buffer overflow in doProlog","severity":"medium","exploited":false,"published_at":"2026-06-19T06:17:10.253+00:00","url":"https://junglewise.ai/threats/cve-2026-56132-libexpat-heap-buffer-overflow-in-doprolog"},{"cve":"CVE-2026-56131","cvss":4.9,"slug":"cve-2026-56131-libexpat-use-after-free-in-xml-resumeparser","title":"libexpat use-after-free in XML_ResumeParser","severity":"medium","exploited":false,"published_at":"2026-06-19T06:17:10.107+00:00","url":"https://junglewise.ai/threats/cve-2026-56131-libexpat-use-after-free-in-xml-resumeparser"},{"cve":"CVE-2026-50219","cvss":4.9,"slug":"cve-2026-50219-libexpat-use-after-free-via-insufficient-handler-call-depth","title":"libexpat use-after-free via insufficient handler call depth tracking","severity":"medium","exploited":false,"published_at":"2026-06-04T06:16:25.05+00:00","url":"https://junglewise.ai/threats/cve-2026-50219-libexpat-use-after-free-via-insufficient-handler-call-depth"},{"cve":"CVE-2026-7210","cvss":9.8,"epss":0.0005,"slug":"cve-2026-7210-python-cpython-denial-of-service-in-xml-parsers","title":"Python CPython denial of service in XML parsers","severity":"critical","exploited":false,"published_at":"2026-05-11T18:16:42.413+00:00","url":"https://junglewise.ai/threats/cve-2026-7210-python-cpython-denial-of-service-in-xml-parsers"},{"cve":"CVE-2026-45186","cvss":2.9,"epss":0.0031,"slug":"cve-2026-45186-libexpat-denial-of-service-via-attribute-name-collision-check","title":"libexpat denial of service via attribute name collision check","severity":"low","exploited":false,"published_at":"2026-05-10T07:16:07.883+00:00","url":"https://junglewise.ai/threats/cve-2026-45186-libexpat-denial-of-service-via-attribute-name-collision-check"},{"cve":"CVE-2026-41080","cvss":2.9,"epss":0.0001,"slug":"cve-2026-41080-libexpat-insufficient-entropy-for-hash-salt-in-xml-parsing","title":"libexpat insufficient entropy for hash salt in XML parsing","severity":"low","exploited":false,"published_at":"2026-04-16T17:16:54.917+00:00","url":"https://junglewise.ai/threats/cve-2026-41080-libexpat-insufficient-entropy-for-hash-salt-in-xml-parsing"},{"cve":"CVE-2026-32778","cvss":2.9,"epss":0.0014,"slug":"cve-2026-32778-libexpat-null-pointer-dereference-in-setcontext-function","title":"libexpat NULL pointer dereference in setContext function","severity":"low","exploited":false,"published_at":"2026-03-16T14:19:44.97+00:00","url":"https://junglewise.ai/threats/cve-2026-32778-libexpat-null-pointer-dereference-in-setcontext-function"},{"cve":"CVE-2026-32777","cvss":4,"epss":0.0022,"slug":"cve-2026-32777-libexpat-infinite-loop-in-entityvalueprocessor-during-dtd-parsing","title":"libexpat infinite loop in entityValueProcessor during DTD parsing","severity":"medium","exploited":false,"published_at":"2026-03-16T14:19:44.78+00:00","url":"https://junglewise.ai/threats/cve-2026-32777-libexpat-infinite-loop-in-entityvalueprocessor-during-dtd-parsing"},{"cve":"CVE-2026-32776","cvss":4,"epss":0.0014,"slug":"cve-2026-32776-libexpat-null-pointer-dereference-in-xml-entity-parsing","title":"libexpat NULL pointer dereference in XML entity parsing","severity":"medium","exploited":false,"published_at":"2026-03-16T14:19:44.6+00:00","url":"https://junglewise.ai/threats/cve-2026-32776-libexpat-null-pointer-dereference-in-xml-entity-parsing"},{"cve":"CVE-2026-25210","cvss":6.9,"epss":0.0001,"slug":"cve-2026-25210-libexpat-integer-overflow-in-docontent-tag-buffer-reallocation","title":"libexpat integer overflow in doContent tag buffer reallocation","severity":"medium","exploited":false,"published_at":"2026-01-30T07:16:15.57+00:00","url":"https://junglewise.ai/threats/cve-2026-25210-libexpat-integer-overflow-in-docontent-tag-buffer-reallocation"},{"cve":"CVE-2026-24515","cvss":2.9,"epss":0.0001,"slug":"cve-2026-24515-libexpat-null-pointer-dereference-in-xml","title":"libexpat NULL pointer dereference in XML_ExternalEntityParserCreate","severity":"low","exploited":false,"published_at":"2026-01-23T08:16:01.49+00:00","url":"https://junglewise.ai/threats/cve-2026-24515-libexpat-null-pointer-dereference-in-xml"},{"cve":"CVE-2025-66382","cvss":2.9,"epss":0.0001,"slug":"cve-2025-66382-libexpat-inefficient-algorithmic-complexity-denial-of-service","title":"libexpat inefficient algorithmic complexity denial of service","severity":"low","exploited":false,"published_at":"2025-11-28T07:15:57.9+00:00","url":"https://junglewise.ai/threats/cve-2025-66382-libexpat-inefficient-algorithmic-complexity-denial-of-service"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Libexpat Project Expat","slug":"expat","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/expat"}],"technology":{"hub":true,"name":"Libexpat Project Libexpat","slug":"libexpat","vendor":{"name":"Libexpat Project","slug":"libexpat-project","url":"https://junglewise.ai/threats/vendors/libexpat-project"},"aliases":["libexpat-project-libexpat"],"category":"library","homepage":"https://libexpat.github.io/","repo_url":"https://github.com/libexpat/libexpat","description":"A stream-oriented XML parser library written in C.","url":"https://junglewise.ai/threats/technologies/libexpat"},"most_severe":[{"cve":"CVE-2026-7210","cvss":9.8,"epss":0.0005,"slug":"cve-2026-7210-python-cpython-denial-of-service-in-xml-parsers","title":"Python CPython denial of service in XML parsers","severity":"critical","exploited":false,"published_at":"2026-05-11T18:16:42.413+00:00","url":"https://junglewise.ai/threats/cve-2026-7210-python-cpython-denial-of-service-in-xml-parsers"},{"cve":"CVE-2024-45492","cvss":9.8,"slug":"cve-2024-45492-libexpat-integer-overflow-in-nextscaffoldpart","title":"libexpat integer overflow in nextScaffoldPart","severity":"critical","exploited":false,"published_at":"2024-08-30T03:15:03.93+00:00","url":"https://junglewise.ai/threats/cve-2024-45492-libexpat-integer-overflow-in-nextscaffoldpart"},{"cve":"CVE-2024-45491","cvss":9.8,"slug":"cve-2024-45491-libexpat-integer-overflow-in-dtdcopy-function","title":"libexpat integer overflow in dtdCopy function","severity":"critical","exploited":false,"published_at":"2024-08-30T03:15:03.85+00:00","url":"https://junglewise.ai/threats/cve-2024-45491-libexpat-integer-overflow-in-dtdcopy-function"},{"cve":"CVE-2026-66046","cvss":7.5,"epss":0.0075,"slug":"cve-2026-66046-expat-xml-parser-denial-of-service-via-quadratic-complexity","title":"Expat XML parser denial of service via quadratic complexity","severity":"high","exploited":false,"published_at":"2026-08-18T15:16:57+00:00","url":"https://junglewise.ai/threats/cve-2026-66046-expat-xml-parser-denial-of-service-via-quadratic-complexity"},{"cve":"CVE-2025-59375","cvss":7.5,"slug":"cve-2025-59375-libexpat-expat-resource-exhaustion-in-xml-parsing","title":"libexpat Expat resource exhaustion in XML parsing","severity":"high","exploited":false,"published_at":"2025-09-15T03:15:40.92+00:00","url":"https://junglewise.ai/threats/cve-2025-59375-libexpat-expat-resource-exhaustion-in-xml-parsing"},{"cve":"CVE-2024-45490","cvss":7.5,"slug":"cve-2024-45490-libexpat-integer-overflow-in-xml-parsebuffer","title":"libexpat integer overflow in XML_ParseBuffer","severity":"high","exploited":false,"published_at":"2024-08-30T03:15:03.757+00:00","url":"https://junglewise.ai/threats/cve-2024-45490-libexpat-integer-overflow-in-xml-parsebuffer"},{"cve":"CVE-2026-25210","cvss":6.9,"epss":0.0001,"slug":"cve-2026-25210-libexpat-integer-overflow-in-docontent-tag-buffer-reallocation","title":"libexpat integer overflow in doContent tag buffer reallocation","severity":"medium","exploited":false,"published_at":"2026-01-30T07:16:15.57+00:00","url":"https://junglewise.ai/threats/cve-2026-25210-libexpat-integer-overflow-in-docontent-tag-buffer-reallocation"},{"cve":"CVE-2026-56411","cvss":6.9,"slug":"cve-2026-56411-libexpat-integer-overflow-in-xmlwf-enddoctypedecl","title":"libexpat integer overflow in xmlwf endDoctypeDecl","severity":"medium","exploited":false,"published_at":"2026-06-21T17:16:44.523+00:00","url":"https://junglewise.ai/threats/cve-2026-56411-libexpat-integer-overflow-in-xmlwf-enddoctypedecl"},{"cve":"CVE-2026-56410","cvss":6.9,"slug":"cve-2026-56410-libexpat-xmlwf-integer-overflow-in-resolvesystemid","title":"libexpat xmlwf integer overflow in resolveSystemId","severity":"medium","exploited":false,"published_at":"2026-06-21T16:16:28.36+00:00","url":"https://junglewise.ai/threats/cve-2026-56410-libexpat-xmlwf-integer-overflow-in-resolvesystemid"},{"cve":"CVE-2026-56408","cvss":6.9,"slug":"cve-2026-56408-libexpat-integer-overflow-in-copystring","title":"libexpat integer overflow in copyString","severity":"medium","exploited":false,"published_at":"2026-06-21T16:16:28.11+00:00","url":"https://junglewise.ai/threats/cve-2026-56408-libexpat-integer-overflow-in-copystring"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}